Author Topic: What is that log? is it repeat?  (Read 3328 times)

0 Members and 1 Guest are viewing this topic.

Liberty

  • Guest
What is that log? is it repeat?
« on: December 13, 2004, 08:09:34 AM »
 
16:40:38 1228 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \SHELL32.dll (\SHELL32.dll) returning error, 0000A413.  
16:50:38 1228 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \mlang.dll (\mlang.dll) returning error, 0000A413.  
17:05:55 1228 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: MSN Messenger\msnmsgr.exe (MSN Messenger\msnmsgr.exe) returning error, 0000A413.  
17:43:28 1228 Sign of "QHA-B [Trj]" has been found in "\shell32.dll" file.  
17:43:32 1228 Sign of "QHA-B [Trj]" has been found in "\urlmon.dll" file.  
19:24:49 1228 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \vbscript.dll (\vbscript.dll) returning error, 0000A413.  
20:42:33 1228 Sign of "Icelandic [4]" has been found in "\SHELL32.dll" file.  
20:44:30 1228 Sign of "Icelandic [4]" has been found in "\wuweb.dll" file.  
20:44:39 1228 Sign of "Icelandic [4]" has been found in "\dllcache\wuweb.dll" file.  
20:45:12 1228 Sign of "Icelandic [4]" has been found in "SoftwareDistribution\SelfUpdate\wuweb.dll" file.  
20:46:13 1228 Sign of "Icelandic [4]" has been found in "\ntoskrnl.exe" file.  
20:46:15 1228 Sign of "Icelandic [4]" has been found in "\drivers\update.sys" file.  
20:46:15 1228 Sign of "Icelandic [4]" has been found in "Common Files\Microsoft Shared\Office10\mso.dll" file.  
20:46:21 1228 Sign of "Icelandic [4]" has been found in "\dllcache\ntoskrnl.exe" file.  
20:46:23 1228 Sign of "Icelandic [4]" has been found in "\dllcache\update.sys" file.  
20:46:24 1228 Sign of "Icelandic [4]" has been found in "\urlmon.dll" file.  
20:46:34 1228 Sign of "Icelandic [4]" has been found in "\SET94.tmp" file.  
20:47:07 1228 Sign of "Icelandic [4]" has been found in "\mlang.dll" file.  
21:27:18 1228 Sign of "Liberty-2857" has been found in "G:\TVR\TVR.exe" file.  
21:27:53 1228 Sign of "Liberty-2857" has been found in "MSN Messenger\msnmsgr.exe" file.  
21:28:48 1228 Sign of "Liberty-2857" has been found in "\SHELL32.dll" file.  
21:32:33 1228 Sign of "Liberty-2857" has been found in "ALWILS~1\Avast4\ashAvast.exe" file.  
21:32:37 3848 Sign of "Liberty-2857" has been found in "d:\standart\util\winrar\rarext.dll" file.  
21:32:57 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\aavm4h.dll" file.  
21:32:58 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\ashbase.dll" file.  
21:32:58 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\ashserv.exe" file.  
21:32:58 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\ashtask.dll" file.  
21:32:58 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\ashuint.dll" file.  
21:32:59 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\aswcmnb.dll" file.  
21:32:59 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\english\lang.dll" file.  
21:33:00 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\unacev2.dll" file.  
21:33:00 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\xerces.dll" file.  
21:33:00 3848 Sign of "Liberty-2857" has been found in "alwil software\avast4\xt1922.dll" file.  
21:33:01 3848 Sign of "Liberty-2857" has been found in "ati technologies\ati control panel\atrpuixx.trk" file.  
21:33:01 3848 Sign of "Liberty-2857" has been found in "clickatell messenger-pro 3\messengerpro.exe" file.  
21:33:02 3848 Sign of "Liberty-2857" has been found in "icqlite\emoextractasset.dll" file.  
21:33:03 3848 Sign of "Liberty-2857" has been found in "icqlite\icqlite.exe" file.  
21:33:05 3848 Sign of "Liberty-2857" has been found in "msn messenger\msnmsgr.exe" file.  
21:33:05 3848 Sign of "Liberty-2857" has been found in "yahoo!\messenger\ft60.dll" file.  
21:33:05 3848 Sign of "Liberty-2857" has been found in "yahoo!\messenger\msvcp71.dll" file.  
21:33:06 3848 Sign of "Liberty-2857" has been found in "yahoo!\messenger\msvcr71.dll" file.  
21:33:06 3848 Sign of "Liberty-2857" has been found in "yahoo!\messenger\res_msgr.dll" file.  
21:33:08 3848 Sign of "Liberty-2857" has been found in "yahoo!\shared\ybskin2.dll" file.  
21:33:08 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\aavm4h.dll" file.  
21:33:08 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\ashavast.exe" file.  
21:33:08 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\ashbase.dll" file.  
21:33:09 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\ashtask.dll" file.  
21:33:09 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\ashuint.dll" file.  
21:33:09 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\aswcmnb.dll" file.  
21:33:10 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\xerces.dll" file.  
21:33:10 3848 Sign of "Liberty-2857" has been found in "alwils~1\avast4\xt1922.dll" file.  
21:33:12 3848 Sign of "Liberty-2857" has been found in "apppatch\acgenral.dll" file.  
21:33:13 3848 Sign of "Liberty-2857" has been found in "\3ivx.dll" file.  
21:33:13 3848 Sign of "Liberty-2857" has been found in "\ac3acm.acm" file.  

...
...
21:34:36 1228 Sign of "Liberty-2857" has been found in "\dllcache\taskmgr.exe" file.  
21:35:31 1228 Sign of "Liberty-2857" has been found in "Alwil Software\Avast4\ashSimp2.exe" file.  
21:37:52 1228 Sign of "Liberty-2857" has been found in "Internet Explorer\iexplore.exe" file.  
21:37:58 1228 Sign of "Liberty-2857" has been found in "\dllcache\iexplore.exe" file.  
23:58:25 996 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.  
23:58:27 996 An error has occured while attempting to update. Please check the logs.  

whocares

  • Guest
Re:What is that log? is it repeat?
« Reply #1 on: December 13, 2004, 10:55:37 AM »
Hi,

some Info on those two file-infectors:

Liberty

Iceland

you could try
- to repair avast:
Controlpanel -> software ->avast ->uninstall -> repair
- and do a subsequent boot-time scan

But I doubt it'll help

if possible confirm and/or Clean the infections with online Scanners, e.g. Trend
-> see link "VirusRemoval" below in my sig

or use avast BART-CD

But if this is not a false positive, I'd advise
- (maybe Data-backup via a Clean Boot-Medium) and then
- FDISK
- FORMAT
- proper reinstall with reliable Setup-Media

Scan all your Floppies & other media for infection afterwards
« Last Edit: December 13, 2004, 10:57:58 AM by whocares »